FlawAtlas
Search the atlas
CVE-2012-1823 Not scored

Confirmed as exploited

PHP-CGI Query String Parameter Vulnerability

sapi/cgi/cgi_main.c in PHP, when configured as a CGI script, does not properly handle query strings, which allows remote attackers to execute arbitrary code.

Exploit probability 100.0%
Published Not available
Required by April 15, 2022
Last source change Not available

01 / ACTION

Required action

Apply updates per vendor instructions.

04 / EVIDENCE

Source records

Cybersecurity and Infrastructure Security Agency Known Exploited Vulnerabilities CVE-2012-1823

sapi/cgi/cgi_main.c in PHP, when configured as a CGI script, does not properly handle query strings, which allows remote attackers to execute arbitrary code.

View original source